Skip to content

Conversation

@wglas85
Copy link

@wglas85 wglas85 commented Jun 27, 2025

This PR fixes CVE-2020-36843 and #95
I did my best to make the project compile and test under openjdk-17 with minimal modifications.
I had to drop support for java-1.7 but hopefully retained compatibility with java-8.
TIA for starting the discussion on this contribution, so that we get this old CVE fixed in 2025.

@arkangelboss-github
Copy link

Thanks!

@wglas85
Copy link
Author

wglas85 commented Jun 27, 2025

Hopefully @str4d is still able to release the project in 2025 and publish it to maven central again. 👍

@wglas85
Copy link
Author

wglas85 commented Aug 1, 2025

@str4d could you please review and hopefully merge this PR?
Thanks in Advance, Wolfgang

@wglas85
Copy link
Author

wglas85 commented Sep 11, 2025

@str4d any news on when we can expect a merge in autumn 2025?
TIA, Wolfgang

@wglas85
Copy link
Author

wglas85 commented Oct 29, 2025

@str4d could you please give us an update on when we can expect when this PR will be merged?
TIA, Wolfgang

Copy link

@seenquev seenquev left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me!

@wglas85
Copy link
Author

wglas85 commented Nov 14, 2025

Looks good to me!

@str4d So, please let's merge and release ecdsa-0.3.1

TIA Wolfgang

@seenquev
Copy link

@wglas85, I've contacted "str4d" over Bluesky communicator, but he hasn't responded me back. My company also relies on that code and we need to patch this vuln. What I've done instead: I pulled the code and compiled it myself into a .jar and source.jar files. Right now, I need to make sure, it works as expected and no regression will result from it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants